US2026025382A1PendingUtilityA1

Access control for shared resources

Assignee: MELLANOX TECHNOLOGIES LTDPriority: Jul 19, 2024Filed: Jul 19, 2024Published: Jan 22, 2026
Est. expiryJul 19, 2044(~18 yrs left)· nominal 20-yr term from priority
H04L 63/102
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Approaches presented herein provide for access control management for shared resources. A request to perform an operation using one or more resources can be analyzed to extract a set of request data, where at least a portion of the request data can be extracted from the request payload. The request data can be compared against an authorization tree for a user, which can include various classes of rules associated with the user role. The actual endpoint for the request can be determined, which may be different from the endpoint otherwise specified for the request, and the appropriate permissions and action determined from the authorization tree. The data to be included in a response can be analyzed using the response tree as well to ensure that no data is included that is otherwise restricted according to the relevant permissions.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A processor, comprising:
 one or more logical units to:
 receive, on behalf of a user, a request for access to at least one resource; 
 extract, from one or more portions of the request including a request payload, a set of request data; 
 compare the set of request data against an authorization tree, the authorization tree specifying one or more classes of rules associated with the user; and 
 determine whether to grant, on behalf of the user, access to the resource based at least in part on an action specified in the authorization tree and corresponding to the set of request data. 
   
     
     
         2 . The processor of  claim 1 , wherein the authorization tree includes a hierarchy of nodes at different levels, the levels including a set of classes of rules at a first level aggregated to a set of roles at a second level, the set of roles aggregated to a set of users at a third level higher than the first and second levels. 
     
     
         3 . The processor of  claim 1 , wherein the action is associated with a path of the request, and wherein individual rules are associated with respective paths and permissions. 
     
     
         4 . The processor of  claim 1 , wherein the request is a restful API request. 
     
     
         5 . The processor of  claim 1 , wherein the set of request data is further extracted from at least one of a header, an endpoint, an address, or a protocol method of the request. 
     
     
         6 . The processor of  claim 1 , wherein multiple rules of the authorization tree are determined to apply to the request and are to be used to determine the action. 
     
     
         7 . The processor of  claim 1 , wherein the one or more logical units are further to generate a request tree and a response tree, and determine whether to grant access further based upon comparing the request tree and the response tree against the authorization tree. 
     
     
         8 . The processor of  claim 1 , wherein child nodes of the authorization tree automatically inherit permissions of a parent node unless otherwise specified. 
     
     
         9 . The processor of  claim 1 , wherein the one or more logical units are further to attempt to authenticate and authorize the request before extracting the set of request data. 
     
     
         10 . A system, comprising:
 one or more processors to:
 extract, from at least a header and a payload of a request received on behalf of a user, a set of request data specifying an endpoint corresponding to an action to be performed; 
 determine, using the set of request data, an actual endpoint corresponding to the action is to be performed; 
 determine, from an authorization tree associated with the user, a permission and an action corresponding to the actual endpoint; and 
 determine whether to grant access to the request based in part on the permission and the action corresponding to the actual endpoint. 
   
     
     
         11 . The system of  claim 10 , wherein the one or more processors are further to:
 generate a request tree using the set of request data; and   compare nodes of the request tree against corresponding nodes of the authorization tree to determine the permission and the action corresponding to the actual endpoint.   
     
     
         12 . The system of  claim 10 , wherein the one or more processors are further to:
 generate a response tree using the set of request data; and   compare nodes of the response tree against corresponding nodes of the authorization tree to determine which data to include in a response generated for the request.   
     
     
         13 . The system of  claim 10 , wherein the authorization tree includes a hierarchy of nodes at different levels, the levels including a set of rules at a first level aggregated to a set of classes at a second level, the set of classes aggregated to a set of roles at a third level higher than the first and second levels. 
     
     
         14 . The system of  claim 10 , wherein the action is associated with one or more rules of a class, and wherein individual rules are associated with respective paths and permissions. 
     
     
         15 . The system of  claim 10 , wherein the one or more processors are to extract the set of request data further from at least one of a header, an endpoint, an address, or a protocol method of the request. 
     
     
         16 . The system of  claim 10 , wherein the system is at least one of:
 a system for performing simulation operations;   a system for performing simulation operations to test or validate autonomous machine applications;   a system for performing digital twin operations;   a system for performing light transport simulation;   a system for rendering graphical output;   a system for performing deep learning operations;   a system for performing generative AI operations using a large language model (LLM);   a system implemented using an edge device;   a system for generating or presenting virtual reality (VR) content;   a system for generating or presenting augmented reality (AR) content;   a system for generating or presenting mixed reality (MR) content;   a system incorporating one or more Virtual Machines (VMs);   a system implemented at least partially in a data center;   a system for performing hardware testing using simulation;   a system for performing generative operations using a language model (LM);   a system for synthetic data generation;   a collaborative content creation platform for 3D assets; or   a system implemented at least partially using cloud computing resources.   
     
     
         17 . A computer-implemented method, comprising:
 extracting, from at least a header and a payload of a request received on behalf of a user, a set of request data specifying an endpoint corresponding to an action to be performed;   determining, using the set of request data, an actual endpoint corresponding to the action is to be performed;   determining, from an authorization tree associated with the user, a permission and an action corresponding to the actual endpoint; and   determining whether to grant access to the request based in part on the permission and the action corresponding to the actual endpoint.   
     
     
         18 . The computer-implemented method of  claim 17 , further comprising:
 generating a request tree using the set of request data; and   comparing nodes of the request tree against corresponding nodes of the authorization tree to determine the permission and the action corresponding to the actual endpoint.   
     
     
         19 . The computer-implemented method of  claim 17 , further comprising:
 generating a response tree using the set of request data; and   comparing nodes of the response tree against corresponding nodes of the authorization tree to determine which data to include in a response generated for the request   
     
     
         20 . The computer-implemented method of  claim 17 , wherein the authorization tree includes a hierarchy of nodes at different levels, the levels including a set of rules at a first level aggregated to a set of classes at a second level, the set of classes aggregated to a set of roles at a third level higher than the first and second levels.

Join the waitlist — get patent alerts

Track US2026025382A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.